
Trojanized npm Package Downloads Cross-Platform Malware for Windows, macOS and Linux
Amazon Threat Intelligence has linked a series of major NPM supply-chain compromises to a Democratic People’s Republic of Korea (DPRK)-linked threat actor. The campaigns targeted trusted open-source JavaScript libraries and delivered malware capable of infecting Windows, macOS, and Linux systems. The actor, tracked as SAPPHIRE SLEET, STARDUST CHOLLIMA, BlueNoroff, CageyChameleon, and Alluring Pisces, allegedly compromised […]
The post Trojanized npm Package Downloads Cross-Platform Malware for Windows, macOS and Linux appeared first on Cyber Security News.